Improper Output Neutralization for Logs Affecting morgan package, versions <1.12.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.39% (33rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Output Neutralization for Logs vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-MORGAN-19784863
  • published14 Sept 2026
  • disclosed11 Sept 2026
  • creditiRevivalx

Introduced: 11 Sep 2026

NewCVE-2026-87859  (opens in a new tab)
CWE-117  (opens in a new tab)

How to fix?

Upgrade morgan to version 1.12.1 or higher.

Overview

morgan is a HTTP request logger middleware for node.js.

Affected versions of this package are vulnerable to Improper Output Neutralization for Logs via the escapeLogField function. An attacker can manipulate log entries by injecting unescaped double quotes into HTTP headers such as User-Agent or Referer, causing log consumers that parse logs by field position to misinterpret attacker-supplied data as subsequent fields.

CVSS Base Scores

version 4.0
version 3.1